What this policy covers
This policy describes information handled by tariffcalc.com during the United States calculator beta. TariffCalc does not sell personal information and does not use calculator results to alter tariff rates.
Privacy and data handling
Effective July 27, 2026 · Policy version 2026-07-27-commercial-legal
This policy describes information handled by tariffcalc.com during the United States calculator beta. TariffCalc does not sell personal information and does not use calculator results to alter tariff rates.
Passwords are stored as one-way password hashes. Verification, password-reset and customer-session tokens are stored as one-way hashes. Raw secrets are not written to application logs.
The beta uses only essential session cookies needed for security, administrator access and customer accounts. No advertising cookie, cross-site tracking pixel or behavioral advertising system is included in this release.
Pilot analytics are server-side and first-party. The approved event records do not contain an IP address, user agent, browser fingerprint, analytics cookie or raw email address. A random flow identifier may connect the steps of one calculator journey, while authenticated account events may use the internal user ID to measure return use.
Unsaved calculator inputs are processed to return a result and are not inserted into the calculation database. User-requested snapshots and active account/workspace records are retained while needed to provide the service, preserve integrity, resolve disputes or meet applicable obligations. Expired security tokens may be removed during maintenance.
Default operational windows are 90 days for raw pilot product events, 365 days for unconverted or finalized pilot applications, 365 days for resolved pilot feedback, 365 days for resolved support requests, 365 days for finalized commercial-interest requests, 180 days for delivery evidence and 730 days for completed account-data request records. Keyed support/commercial rate-limit attempt evidence is removed after two days when the protected cleanup is applied. A specific record may be retained longer for an open request, security investigation, dispute, legal hold or other applicable obligation. Finalized support/commercial records are eligible for cleanup only after their resolution/update boundary, not merely because the original request is old.
An authenticated account holder can immediately export saved calculation history and can submit an audited full-export, correction or deletion request through Account Data Controls. Deletion requests require password reauthentication, the exact confirmation phrase and a default seven-day cooling-off period. They do not cause immediate automatic deletion. An operator verifies scope, workspace ownership and retention duties before any destructive execution. Some deidentified, integrity, security, financial or legal records may remain after closure. Privacy questions may also be sent to support@tariffcalc.com.
Hosting, email and security providers may process the minimum information needed to operate their service. When transactional email is enabled, the configured provider receives the recipient address and message needed to deliver verification, reset or invitation email. Email open and link tracking are disabled in the supplied Postmark integration. Official tariff sources linked from TariffCalc are operated by third parties and have their own privacy practices.
Privacy or security-handling questions may be sent to support@tariffcalc.com. Do not send passwords, private keys, payment data or unrelated customer records. A material policy change will receive a new version and effective date.